Defence Assurance and Information Security (DAIS) defence industry ICT accreditation and risk balance case (RBC) processes.
DAIS provides a range of support to defence and its industry partners in the area of information assurance (IA), including:
- oversight, tracking and provision of management information for all defence accreditation activity
- advice and guidance on the subject of accreditation
- assessment of evidence submitted in support of the accreditation process; e.g. risk management accreditation document sets (RMADS) and security operating procedures (SyOPs)
- final sign-off and provision of a certificate and letter of accreditation
- progression and review of risk balance cases (RBC) prior to sign-off by Ministry of Defence (MOD) Senior Information Risk Owner (SIRO)
Accreditation confirms that information and communication technology (ICT) systems embody appropriate security to allow MOD information to be stored and processed with an acceptable level of risk.
The Defence Assurance Risk Tool (DART) (opens DART for those with restricted LAN interconnect (RLI) access) must be used to register all ICT systems owned or used by MOD industry partners, where those ICT systems are either connected to Her Majesty’s Government networks or store or process OFFICIAL-SENSITIVE information or more highly classified information. These ICT systems must be accredited before use and subsequently have their security managed thereafter.
The authorities responsible for the systems requiring accreditation must ensure that this accreditation is obtained before storing or processing MOD information.
DAIS is the sponsor of the accreditation process for MOD, providing support and advice and overseeing accreditation activity across defence. The system, or a subset of a system, requiring accreditation is known as a target of assurance (TOA).
All requests to accredit ICT are processed through the Defence Assurance Risk Tool (DART), which enables the tracking of TOAs and the provision of management information.
The DART methodology includes a triage process that takes account of risk and assigns one of the following assessment paths:
- DAIS assessment (known as ‘Red Channel’)
- MOD Top Level Budget Holder accreditor assessment (‘Amber Channel’)
- self assessment and provision of evidence to DAIS (‘Green Channel’)
Accreditation requires the provision of evidence and approval through the Defence Assurance and Information Security (DAIS) team (opens for those with RLI access) or delegated authority processes and will result in a DART generated certificate and letter.
The requirement to register systems for accreditation through DART is specified within Industry Security Notice (ISN) 2017/01.
Risk balance cases
Where circumstances dictate that it is necessary to carry out action that is outside of the scope of standard policy, an risk balance cases (RBC) must be raised. As with accreditation, all RBCs are registered through DART, providing the user is able to connect to the RLI.
RBCs are divided into 2 main categories:
- movements: involving the transfer of information between various locations; these were formerly referred to as ‘Fast Tracks’
- information: all other RBCs (previously called ‘Supp 12’s’)
The generic pathway for an RBC is:
- initial triage by DAIS to determine who needs to be involved
- review and comment by nominated stakeholders; e.g. the Network Technical Authority or local security staff.
- review and comment by a DAIS accreditor
- a final assessment by the DAIS RBC lead
- approval by MOD SIRO or delegated authority
Start accrediting your ICT system or registering an RBC
- Register a system/application that requires accreditation or an RBC (opens DART for those with RLI access).
- If you have not used DART before, you will need to register first by clicking on ‘New account’; if you have, click ‘Login’.
- Follow the instructions within the tool; if you get stuck, open the user guide by clicking on the ‘?’ icon at the top of the screen.
If you do not have access to the RLI, you will not be able to access DART directly. In this circumstance:
- Save a copy of the relevant DAIS accreditation request or off-line RBC form to a suitable location.
- Remember that information categorised as OFFICIAL-SENSITIVE or above must not be transmitted in clear over the internet.
- Post the completed accreditation request forms to:
Service Delivery Team
DAIS, Room X007
Get advice and guidance on the accreditation or RBC processes in general.
Call our customer support line on 01480 446311 or 95371 4564 or email firstname.lastname@example.org.
Find out who the accreditor is for your system or the progress against an RBC that you have submitted
- Login to DART (opens DART for those with RLI access) and click on the ‘+’ sign against the relevant line item to ascertain the current status of the submission and to whom it has been allocated.
- The link above will provide you with access to the ‘Survey Responder’ element of DART, which is required in order to register either a system for accreditation or an RBC. Accreditors, and those with a need to view multiple Targets of Accreditation or RBCs, will require access to DART CMS (case management system). Applications for DART CMS accounts should be submitted through the DAIS Service Delivery Team.
- If you do not have a DART account but need to know, call our customer support line on 01480 446311 or 95371 4564 or email email@example.com.
Joint Security Co-ordination Centre
The Joint Security Co-ordination (JSyCC) enables ‘defence information assurance’ assessment through the conduct and coordination of MOD information security incident management and related risk analysis activity.
Additionally, it is a focal point for ‘information security alerts’ and associated ‘warning and response’ activities.
JSyCC are responsible for:
- operational co-ordination and management of the immediate response, warning and reporting, including the investigative oversight and follow-up actions, for all reported defence information assurance/information security incidents involving the loss, compromise or leakage of protectively marked official information and/or equipment
- operational information security risk management, trend analysis and related policy. This includes the management of the MOD Information Security Incident Reporting Scheme (MISIRS) and supporting database, together with the drafting of responses to Parliamentary Questions, Freedom of Information (FOI) requests etc
- the provision of the defence industry warning and reporting point (WARP) responsible for the coordination of the response and management of all defence industry information security incidents, including List X
- the coordination of all law enforcement and counter intelligence for information security incidents
If you want to know more about JSyCC, use the contact details below:
X017, Bazelgette Pavilion
Cambs, PE28 2EA
Point of Contact: JSyCC Ops 0306 770 2187
JSyCC Duty Officer (out of hours) 07768 558 863